# Researcher reports Android C2PA camera-signing forgery path

_Tuesday, August 25, 2026 at 3:38 PM EDT · Security, Products · Latest · Tier 2 — Notable_

Security researcher David Buchanan reported that Android C2PA camera applications relying on Key Attestation or Google Play Integrity can be induced to sign arbitrary media after a device is rooted through a privilege-escalation exploit or hardware fault attack. He said this could let forged images or videos carry camera-provenance signatures. Buchanan wrote that Google closed his report as infeasible to fix and awarded a $7,500 bounty, while a cited software exploit path could still be patched.

## Sources

- [da.vidbuchanan.co.uk](https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html)

---
Canonical: https://techandbusiness.org/newswire/xD7wYNlh3BVMcvGc8PFC2V
Retrieved: 2026-08-26T04:55:27.939Z
Publisher: Tech & Business (techandbusiness.org)
